Who Is Your Security Official? A HIPAA Requirement You Have Probably Already Met
August 17, 2026 · 6 min read
Ask a dental practice owner who decides whether the new front desk hire gets her own login, and you get an answer right away. Ask who calls the IT company when the computer at the front does something strange. Also an immediate answer. Ask who says yes or no when a software company wants access to the practice management database, and there is a name.
Then ask who the practice's security official is, and the room goes quiet.
That is the whole gap, and it is smaller than it looks. The practice is not missing a role. It is missing a sentence.
What the rule actually says
The HIPAA Security Rule contains this, at 45 CFR 164.308(a)(2), under the heading Standard: Assigned security responsibility:
"Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate."
That is the entire provision. One sentence, and nothing follows it.
Notice what is not there. Most of section 164.308 asks a practice to weigh things. Is log-in monitoring reasonable for an office this size. Is a particular password practice appropriate here. Those are addressable specifications, which means a practice implements them, implements an equivalent alternative, or documents why neither is appropriate.
Assigned security responsibility has nothing underneath it at all. There is nothing to weigh and no alternative to write down. Either you have identified the person or you have not. Of everything in that section, this is the one a practice can finish today.
Two requirements, one person, three designations
Here is the part that almost nobody explains, and it is where practices quietly come up short.
The Security Rule says to identify the security official. Separately, in a different subpart, adopted in a different rulemaking, the Privacy Rule at 45 CFR 164.530(a)(1) says a covered entity must designate a privacy official, and must designate a contact person or office responsible for receiving complaints.
Add those up and a dental practice owes three designations across two rules. One person may hold all three. That is three requirements satisfied, not one.
HHS has said the comparison in its own words for two decades. Its Security Rule guidance for the administrative safeguards states that this standard is "comparable to the Privacy Rule standard at §164.530(a)(1), Personnel Designations," and that the security official and privacy official "can be the same person, but are not required to be." When the Office for Civil Rights proposed updates to the Security Rule in January 2025, it repeated that same explanation nearly word for word.
The practical consequence is specific. A practice with "a HIPAA person" tends to believe one designation covers everything, and has usually documented one thing. The Privacy Rule expressly requires the personnel designations be documented. The Security Rule's parallel sentence says only "identify," which is exactly the asymmetry OCR proposed to close.
What the job is in a four-operatory office
HHS is direct that this role scales to the practice. Its own guidance asks whether it would serve the organization's needs to designate the same individual as both officials, "for example, in a small provider office," and how the responsibilities of the security official are "crafted to reflect the size, complexity and technical capabilities of the organization."
NIST's companion guidance for the Security Rule describes the person as a point of contact for security policy, implementation, and monitoring. Point of contact. Not engineer.
Translated into a working practice, the security official is the answer to questions like these:
-
Who signs off when the IT company recommends new equipment or a new service
-
Who asks a software company what it will read and write before the practice goes live on it
-
Who reads the risk analysis when it comes back and decides what happens next
-
Who decides how a departing team member's access ends, and when
And then the best question in the NIST guidance, the one that tells an owner immediately whether the designation is real: have the members of your team been told whom to call if something looks wrong?
If four people would give four different answers, the designation exists on paper and nowhere else.
One name at the top, several people holding pieces
This is the part that makes the requirement livable. HHS states that while one individual must be designated as having overall responsibility, other individuals in the practice may be assigned specific security responsibilities. NIST puts it more bluntly: the security official may enlist help, but final responsibility is assigned to one individual.
So the office manager can own the login list. The IT company can own the firewall and the backups. The owner can own vendor access decisions. One name still sits at the top of all of it, and everyone knows the name.
That is not a technical arrangement. It is an ownership arrangement, and it is the kind of thing a practice usually knows informally and has never written down.
Write it down where the team will actually look
A designation that lives in one person's memory disappears when that person does. A designation that lives in a binder nobody opens is only slightly better.
The version that holds is the one stored with the rest of how the practice runs, next to the procedure for a new hire's first week and the answer to who calls the IT company. That is where a new office manager will go looking, and it is the difference between a practice that has a security official and a practice that has a name on a form.
This is the kind of thing Saige exists for. It keeps a practice's procedures, ownership, and internal answers in one place your team can search, so "who is responsible for this" is a question with a findable answer rather than a hallway conversation. If you want to see how that works in a real practice, take a look at Saige. No contracts and no onboarding fee.
One thing worth watching
In January 2025 OCR proposed renumbering this standard and requiring that the security official be identified in writing, noting from its enforcement experience that many organizations had never documented the identification at all. That proposal has not been finalized. It has moved to the long-term regulatory agenda, with final action anticipated in 2027, and the current Security Rule remains in effect in the meantime.
Which is a long way of saying the direction is obvious. A practice that names the person and writes it down is already where the rule is going.
Deren Flesher, DDS. Founder, AiroDental.
Frequently asked questions
- Can the same person be our privacy official and our security official?
- Yes. HHS says so directly in its own Security Rule guidance: the security official and the privacy official "can be the same person, but are not required to be," and its sample questions raise the small provider office as the obvious case. What matters is that both designations exist and both are written down. Naming one person to hold both is one person satisfying two requirements, not one requirement.
- Does the security official have to be someone technical?
- No, and the rule never asks for one. NIST's guidance for implementing the Security Rule describes the person as the point of contact for security policy, implementation, and monitoring. HHS asks that the responsibilities be "crafted to reflect the size, complexity and technical capabilities of the organization." In most practices the right answer is the owner or the office manager, with the IT company handling the technical work underneath them.
- Can our IT company be our security official?
- The standard says to identify the security official responsible for developing and implementing the practice's policies and procedures, and it is written to the covered entity. Practically, the person carrying overall responsibility should be inside the practice, because that responsibility includes deciding what happens next when the IT company makes a recommendation. HHS is explicit that other individuals may be assigned specific security responsibilities while one person holds overall responsibility, which is exactly where an outside IT partner fits.
- Where should the designation be documented?
- The Privacy Rule expressly requires that the personnel designations be documented. The Security Rule's parallel sentence does not say that, though it does require written policies and procedures generally, and OCR has proposed adding the words "in writing" to the security official standard. So the safe and simple answer is to write it down now, and to store it where a new office manager would actually look for it rather than in a binder nobody opens.
- What happens to the designation when that person leaves the practice?
- It has to be re-made, and it is easy to miss in the middle of everything else a departure creates. If the office manager was the security official and the practice does not name a successor, the requirement is unmet from the day she leaves. The same is true of the privacy official designation and the complaints contact. This is one of a small number of obligations a departure triggers on its own.
Related articles
When a Patient Asks the Assistant
The doctor steps out and the patient asks the assistant what she would do. The ADA has drawn her line in a different place from the front desk's, and the state practice act draws it again by how close the dentist has to be. Neither is where most practices assume.
October 7, 2026 · 7 min read
AiroDental Raises $0 to Keep Dental AI Accountable to Dentists
AiroDental today announced that it has raised $0 in outside funding. No venture capital, no private equity, no debt, no board. Founder Deren Flesher, DDS, a practicing dentist in Edmond, Oklahoma, owns 100 percent of the company, and explains why the person deciding what dental software does should be someone who has to use it in a dental practice.
September 8, 2026 · 5 min read
What Your Software Counts as Unscheduled
Four practices pull the same report on the same morning and get four numbers. None of them is comparable to the others, and none of them is wrong. The systems differ on whether they count people or procedures, which date the report hangs on, and whether the number is even current. Here is what each one actually counts.
September 2, 2026 · 7 min read